How to implement AI under NIST 800-171
The short answer
AI is allowed under NIST 800-171 and CMMC. What decides compliance is the deployment pattern, not the model brand. If an external provider hosts the model, DFARS 252.204-7012(b)(2)(ii)(D) makes you responsible for ensuring it meets FedRAMP-Moderate-equivalent security; if you host the model inside your own boundary, that test disappears and plain NIST SP 800-171 applies to the system it runs on. The same vendor is routinely a yes in its government cloud and a no in its commercial tenant. Implementation is a five-step sequence: map your CUI flows, classify each tool’s pattern, verify the authorization evidence, scope the controls, and document it in your SSP.
The three deployment patterns
Every AI tool question reduces to which of these three shapes it takes. The verdicts below link to per-tool pages where every claim carries a primary source — the vendor’s own documentation, the FedRAMP Marketplace record, or the regulation text.
Commercial multi-tenant SaaS
The default consumer or enterprise tenant. An external cloud service provider is in the path, so DFARS 252.204-7012(b)(2)(ii)(D) applies and the question becomes what that provider is authorized to hold.
Government cloud / sovereign variant
A separately operated environment (GCC High, Azure Government, AWS GovCloud, Assured Workloads) with its own authorization record. Same brand, different boundary — and the AI features available inside it are frequently a subset.
In-boundary / self-hosted inference
The model runs on systems the contractor owns or operates inside its own CUI enclave. No external cloud service provider is in the path, so the FedRAMP-equivalency paragraph is not the operative test — NIST SP 800-171 applied to your own system is.
What the regulation actually says
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
— DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting (Acquisition.gov (DFARS, MAY 2024 revision), retrieved 2026-07-27)
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
— DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting (Acquisition.gov (DFARS, MAY 2024 revision), retrieved 2026-07-27)
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
— NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST Computer Security Resource Center, retrieved 2026-07-27)
The five-step implementation sequence
- 1
Map where CUI actually moves
You cannot scope an AI deployment against flows you have not mapped. Chart which systems hold CUI, where it enters and leaves, and which people and processes touch it.
CUI Flow Mapper → - 2
Classify each AI tool’s deployment pattern
Commercial SaaS, government cloud, or in-boundary. The pattern — not the brand — selects which test applies.
AI Tool CUI Checker (13 verdicts) → - 3
Verify the authorization evidence
For any external provider in the path: the FedRAMP Marketplace record, its impact level, and whether the environment named in the record is the one you would actually use.
FedRAMP Finder → - 4
Scope the controls the deployment touches
Access control, audit and accountability, and system and communications protection carry most of the load. Your SPRS score already prices the gaps.
SPRS Score Calculator → - 5
Document it in the SSP and attest
Pattern, boundary, evidence, flows, mediating controls — or the technical control that keeps CUI away from an out-of-boundary tool. Post-pause, your attestation is the record.
How the assessment builds this for you →
Frequently asked
Can I use AI tools at all under NIST 800-171?
Yes. Neither NIST SP 800-171 nor CMMC prohibits AI. The requirement is that any system that processes, stores or transmits CUI — an AI assistant included — sits inside a compliant boundary. What decides the answer is the deployment pattern: commercial multi-tenant SaaS, a government cloud variant, or self-hosted inference inside your own enclave.
What makes a commercial AI tool non-compliant for CUI?
Not the model — the boundary. A commercial AI endpoint is an external cloud service provider, so DFARS 252.204-7012(b)(2)(ii)(D) requires the contractor to ensure it meets security requirements equivalent to the FedRAMP Moderate baseline, plus the clause’s incident-reporting and forensics paragraphs. Most commercial AI tenants have no such authorization record, which is why the same vendor can be a yes in its government cloud and a no in its commercial one.
Does self-hosting an open-weight model remove the FedRAMP question?
It removes the external-cloud-service-provider test, because no external provider is in the path. It does not remove NIST SP 800-171: the system the model runs on is a covered contractor information system, and the access-control, audit, and boundary-protection families apply to it like any other in-scope system.
Which NIST 800-171 control families matter most for an AI deployment?
Access control (who and what can reach the assistant and what it can reach), audit and accountability (prompts and outputs that touch CUI are records of CUI access), and system and communications protection (where inference happens and what crosses the boundary). An assistant that reaches CUI must live in the same access, logging and boundary regime as any other system that touches it.
Did the 2026 CMMC pause change what AI tools I can use?
No. The July 2026 pause halted third-party certification assessments; it did not change DFARS 252.204-7012, NIST SP 800-171, SPRS scoring, or annual affirmations. With no assessor in the path, your own attestation carries the record — which makes "can this tool touch CUI" a sharper question, not a softer one.
How do I document an AI tool in my SSP?
Treat it as a system component: record the deployment pattern, the boundary it sits in, the authorization evidence for any external provider (FedRAMP Marketplace record or equivalency package), the CUI flows that reach it, and the controls that mediate those flows. If it is out of boundary, document the technical control that keeps CUI away from it — policy alone is not a boundary.
Working on this for real?
Reading a clause is the easy part. Deciding what to build, in what order, and what it costs is the work.
- See how the assessment works — the AI Integration Assessment: a sequenced, costed plan, $12,500, fixed scope.
- Apply for an evaluation — we don't take every client. Qualified applications book instantly; pilots ($6,000–$45,000, one workflow in your boundary) are reviewed for strategic fit.